home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eggblog | Epic_designs | * | 3.0.6 (including) |
Eggblog | Epic_designs | 2.0 (including) | 2.0 (including) |
Eggblog | Epic_designs | 3.0 (including) | 3.0 (including) |